Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (2024)

NIST 800-171 control 3.13.11 dictates that FIPS-validated cryptography is used when protecting the confidentiality of CUI. BitLocker is FIPS-validated, but it requires a setting before encryption that ensures that the encryption meets the standards set forth by FIPS 140-2. When encrypting devices with BitLocker, please be sure to follow the steps below to ensure that the encryption used is within parameters of control 3.13.11.

Option 1: Local Security Policy

  • Open Local Security Policy as administrator
  • Navigate to Local Policies =>Security Options
  • Set System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing to be Enabled
  • Then, encrypt the machine using BitLocker

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (1)

Option 2: Domain Group Policy

  • Open Group Policy Management
  • Choose one of the following options:
    • To use an existing GPO to configure the necessary setting, link the _Campus-NIST800-171-FIPS-Compliant-BitLocker GPO to the OU where the computers in question reside.
    • Otherwise: Locate an existing GPO or create a new GPO, right click it, and then select Edit
      • When the Group Policy Management Editor opens, navigate to Policies =>Windows Settings =>Security Settings =>Local Policies =>Security Options
      • Locate System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing and open it

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (2)

      • Ensure the policy is defined and set to Enabled, and then click OK.

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (3)

  • Ensure the GPO is applied to the machine to be encrypted with BitLocker.
  • Finally, encrypt the machine with BitLocker.

Special Case: Windows 7 Machine

If the machine is a Windows 7 machine, another step will need to be completed. As recovery passwords aren’t FIPS 140-2 compliant, any recovery passwords will need to be removed. This issue was resolved in Windows 8 and above. To ensure the Windows 7 machine is compliant:

  • Open CMD as an administrator
  • Run the following command:
    • manage-bde -protectors -get c:
      • Be sure to replace “c:” with the letter of the encrypted drive.
    • In the result, locate ID: under Numerical Password: and copy the value
      • Example value: {C6DF1E74-467F-4BE8-9C59-C9A9F345B9A0}

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (4)

  • When you have the value, run the following command to delete the recovery password:
    • manage-bde -protectors -delete c: -id {########-####-####-####-############}
      • Again, be sure to replace the drive letter as necessary.

Recovery Options

To ensure the drive is recoverable, a few options are:

Additional Information

For more information, please navigate to this link: How to Make Your Existing BitLocker Encrypted Environment FIPS Compliant

Control 3.13.11 Information – BitLocker Setup – DFARS/NIST 800-171 Compliance Program (2024)
Top Articles
Our shareholders
256 Reasons to Celebrate Programmer’s Day
Craigslist Free Stuff Appleton Wisconsin
San Diego Terminal 2 Parking Promo Code
Songkick Detroit
Unlocking the Enigmatic Tonicamille: A Journey from Small Town to Social Media Stardom
Fototour verlassener Fliegerhorst Schönwald [Lost Place Brandenburg]
Vanadium Conan Exiles
City Of Spokane Code Enforcement
Best Restaurants In Seaside Heights Nj
OnTrigger Enter, Exit ...
Snowflake Activity Congruent Triangles Answers
Edgar And Herschel Trivia Questions
Oriellys St James Mn
Sport Clip Hours
Bc Hyundai Tupelo Ms
WWE-Heldin Nikki A.S.H. verzückt Fans und Kollegen
Price Of Gas At Sam's
Les Rainwater Auto Sales
Tamilrockers Movies 2023 Download
Niche Crime Rate
Vipleaguenba
Aspen Mobile Login Help
Earl David Worden Military Service
Dwc Qme Database
The Many Faces of the Craigslist Killer
Inkwell, pen rests and nib boxes made of pewter, glass and porcelain.
Mta Bus Forums
FAQ's - KidCheck
Everything You Need to Know About Ñ in Spanish | FluentU Spanish Blog
Advance Auto Parts Stock Price | AAP Stock Quote, News, and History | Markets Insider
Moonrise Time Tonight Near Me
Craigslist Com Humboldt
Austin Automotive Buda
Viewfinder Mangabuddy
Lamp Repair Kansas City Mo
Despacito Justin Bieber Lyrics
Smite Builds Season 9
Todd Gutner Salary
Pgecom
How the Color Pink Influences Mood and Emotions: A Psychological Perspective
Ups Customer Center Locations
Learn4Good Job Posting
Benjamin Franklin - Printer, Junto, Experiments on Electricity
Race Deepwoken
Mikayla Campinos Alive Or Dead
What Time Do Papa John's Pizza Close
Besoldungstabellen | Niedersächsisches Landesamt für Bezüge und Versorgung (NLBV)
Southwind Village, Southend Village, Southwood Village, Supervision Of Alcohol Sales In Church And Village Halls
Download Twitter Video (X), Photo, GIF - Twitter Downloader
Latest Posts
Article information

Author: Sen. Emmett Berge

Last Updated:

Views: 5694

Rating: 5 / 5 (60 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Sen. Emmett Berge

Birthday: 1993-06-17

Address: 787 Elvis Divide, Port Brice, OH 24507-6802

Phone: +9779049645255

Job: Senior Healthcare Specialist

Hobby: Cycling, Model building, Kitesurfing, Origami, Lapidary, Dance, Basketball

Introduction: My name is Sen. Emmett Berge, I am a funny, vast, charming, courageous, enthusiastic, jolly, famous person who loves writing and wants to share my knowledge and understanding with you.